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DETAILED ACTION 
Claim Rejections - 35 USC § 102 

1 . The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that 
form the basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(e) the invention was described in (1) an application for patent, published under section 122(b), by 
another filed in the United States before the invention by the applicant for patent or (2) a patent 
granted on an application for patent by another filed in the United States before the invention by the 
applicant for patent, except that an international application filed under the treaty defined in section 
351(a) shall have the effects for purposes of this subsection of an application filed in the United States 
only if the international application designated the United States and was published under Article 21(2) 
of such treaty in the English language. 

2. Claims 1-16 are rejected under 35 U.S.C. 102(e) as being anticipated by Kwan et 
al., US 2004/0255154. 

In claim 1, Kwan discloses a method for detecting unauthorized hardware 
devices in a local area network, comprising steps of: 

scanning ports of a plurality of hardware devices to retrieve MAC addresses 
thereof (paragraphs [0009]-[0011], [0024], [0036]); 

filtering an uplink port on each of the hardware devices to acquire a first MAC 
address list (paragraphs [0009H0011], [0024], [0051]-[0052]); 

calculating the number of MAC addresses of the filtered ports to acquire a 
second MAC address list (paragraphs [0036]-[0037]); and 

subtracting the number of ports with more than two MAC addresses on the first 
MAC address list from the number of ports with more than two MAC addresses on the 
second MAC address list, thereby obtaining at least one unauthorized MAC address 
(paragraphs [0036]-[0037], [0051]-[0052]). 
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In claim 2, Kwan discloses the method as claimed in claim 1 , further comprising 
steps of: 

comparing the MAC addresses of the unauthorized hardware devices with MAC 
addresses in a routing entry table to obtain Internet Protocol (IP) addresses of the 
unauthorized hardware devices (paragraphs [0010]-[0011], [0031], [0036]); and 

acquiring user information for the unauthorized hardware devices by SNMP or 
WINS services in accordance with the IP address of the unauthorized hardware devices 
(paragraph [0044]). 

In claim 3, Kwan discloses the method as claimed in claim 1, wherein in the 
scanning step, the ports of the authorized hardware devices are recursively scanned by 
one of the authorized network devices (paragraphs [0009]-[0011], [0024], [0036], 
[0051]-[0052]). 

In claim 4, Kwan discloses the method as claimed in claim 1, wherein in the 
scanning step, the MAC addresses of authorized hardware devices are stored in a 
database (paragraphs [0051]-[0052]). 

In claim 5, Kwan discloses the method as claimed in claim 1, wherein in the 
scanning step, the ports of authorized network devices are scanned by simple network 
management protocol (paragraph [0044]). 

In claim 6, Kwan discloses the method as claimed in claim 1 , wherein a simple 
network management protocol is used in the calculating step (paragraph [0044]). 

In claim 7, Kwan discloses a system for detecting unauthorized hardware devices 
in a local area network, comprising: 
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a device detection unit for scanning a plurality of ports of a plurality of hardware 

* 

devices to retrieve MAC addresses thereof, filtering an uplink port of each hardware 
device to acquire a first MAC address list, and calculating the number of MAC 
addresses of the ports of the network devices to acquire a second MAC address list 
(paragraphs [0009]-[0011], [0024], [0036]-[0037], [0051]-[0052]); and 

a device processing unit, coupled with the device detection unit, for subtracting 
the number of ports with more than two MAC addresses on the first MAC address list 
from the number of ports with more than two MAC addresses on the second MAC 
address list, thereby obtaining at least one unauthorized MAC address (paragraphs 
[0036]-[0037], [0051]-[0052]). 

In claim 8, Kwan discloses the system as claimed in claim 7, wherein the device 
processing unit compares the MAC addresses of the unauthorized hardware devices 
with MAC addresses in a routing entry table to obtain Internet Protocol (IP) addresses of 
unauthorized hardware devices, and acquire user information of the unauthorized 
hardware devices by SNMP or WINS services (paragraph [0044]). 

In claim 9, Kwan discloses the system as claimed in claim 7, wherein the device 
detection unit recursively scans the ports of the hardware devices (paragraphs [0009]- 
[0011], [0024], [0036], [0051]-[0052]). 

In claim 10, Kwan discloses the system as claimed in claim 7, wherein the device 
detection unit stores the MAC addresses of the hardware devices in a database 
(paragraphs [0051 ]-[0052]). 
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In claim 11, Kwan discloses the system as claimed in claim 7, wherein the device 
detection unit scans the ports of the network devices by simple network management 
protocol (paragraph [0044]). 

In claim 12, Kwan discloses a storage medium containing a stored computer 
program providing a method for detecting unauthorized hardware devices, comprising 
using a computer to perform the steps of: 

scanning a plurality of ports of a plurality of hardware devices to retrieve MAC 
addresses thereof (paragraphs [0009]-[0011], [0024], [0036]); 

filtering an uplink port of each hardware device to acquire a first MAC address list 
(paragraphs [0009]-[0011], [0024], [0051]-[0052]); 

calculating the number of MAC addresses of the ports of the network devices to 
acquire a second MAC address list (paragraphs [0036]-[0037]); and 

subtracting the number of ports with more than two MAC addresses on the first 
MAC address list from the number of ports with more than two MAC addresses on the 
second MAC address list, thereby obtaining at least one unauthorized MAC address 
(paragraphs [0036]-[0037], [0051]-[0052]). 

In claim 13, Kwan discloses the storage medium as claimed in claim 12, further 
comprising steps of: 

comparing the MAC addresses of the unauthorized hardware devices with MAC 
addresses in a routing entry table to obtain Internet Protocol (IP) addresses of 
unauthorized hardware devices (paragraphs [0010]-[0011], [0031], [0036]); and 
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acquiring user information of the unauthorized hardware devices by SNMP or 
WINS services in accordance with the IP address of the unauthorized hardware devices 
(paragraph [0044]). 

In claim 14, Kwan discloses the storage medium as claimed in claim 12, wherein 
the ports of the hardware devices are recursively scanned by one of the authorized 
network devices (paragraphs [0009]-[0011], [0024], [0036], [0051]-[0052]). 

In claim 15, Kwan discloses the storage medium as claimed in claim 12, wherein 
the MAC addresses of the hardware devices are stored in a database (paragraphs 
[0051]-[0052]). 

In claim 16, Kwan discloses the storage medium as claimed in claim 12, wherein 
the ports of the network devices are scanned by simple network management protocol 
(paragraph [0044]). 

Conclusion 

3. The prior art made of record and not relied upon is considered pertinent to 
applicant's disclosure: Hammons et al., US 2006/0080727; Poletto et al., US 
2005/0033989; Williams et al., US 2005/0015623; Ginter et al., US 2005/0015624; 
Knight, US 2004/0255167; Bearden et al., US 2003/0097438. 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Jaric Loving whose telephone number is (571) 272- 
1686. The examiner can normally be reached on Monday-Friday. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Emmanuel Moise can be reached on (571) 272-3865. The fax phone 
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number for the organization where this application or proceeding is assigned is 571- 
273-8300. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information 
system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 
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